
The 30-second version
- Privacy compliance is no longer a “California problem” or a “Europe problem.” By January 1, 2026, almost 25 U.S. states had consumer privacy laws in effect.
- U.S. law is simpler than Europe’s: You generally need to tell visitors what you collect, give them an easy way to opt out, and automatically honor a do-not-sell signal that some browsers send.
- Enforcement is real and rising. In 2026, multiple settlements amounted to millions of dollars, with regulators specifically targeting broken opt-out and consent setups.
- Google changed its rules too: As of June 2026, your website’s consent setup is now the main control over what data Google Ads can collect — so getting it wrong now also hurts your ad performance.
The State of U.S. Privacy and Cookie Compliance
A plain-English briefing for our clients — where the law stands today and why it’s time to act
1. It’s no longer just California
For years, “online privacy law” meant Europe’s GDPR or California’s CCPA. That has changed. As of January 2026, almost 25 U.S. states have their own comprehensive consumer privacy laws in effect,1, 2 covering more than half the country’s population.
States with active laws include California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Nebraska, Indiana, Kentucky, and Rhode Island (Florida has a narrower law).2 Even when a business operates in just one state, these laws can apply based on where your visitors live — not where your office is.
2. What U.S. law actually asks of you
Here is the good news for U.S.-focused businesses: The American approach is lighter than Europe’s. Europe’s GDPR generally requires you to ask permission before any tracking (opt in). Most U.S. state laws instead use an opt-out model. In plain terms, you generally need to:
- Tell visitors what data you collect and why (with a clear privacy and cookie notice).
- Give them an easy way to opt out of having their personal information sold or shared — the familiar “Do not sell or share my personal information” link.
- Automatically honor the browser do-not-sell signal (more on this in the next section).
This matters because it means a U.S.-focused business usually does not need an aggressive “Click ACCEPT before anything loads” banner. A lighter notice and opt-out approach keeps your analytics and advertising working while staying compliant.
3. The browser signal you can’t ignore
The single biggest technical change in recent years is the global privacy control (GPC) — a browser setting that automatically says, “Don’t sell my information.” Around a dozen states, including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Jersey, New Hampshire, Texas, and Oregon,3 now legally require websites to detect and honor this signal automatically.
The important point: A visitor does not have to click anything on your site. If their browser sends the signal and your site ignores it, you may be out of compliance — even if you have a cookie banner. Modern consent tools detect and honor this signal automatically.
4. Enforcement now has real teeth
This is the part that makes 2026 different. Regulators are no longer just issuing warnings. California’s maximum fines were adjusted upward in 2026 to about $2,663 per violation for unintentional breaches and $7,988 for intentional ones or those involving minors.6, 7 Crucially, those amounts can be counted per affected consumer, so on a busy website the totals add up fast.
Recent U.S. settlements show the trend — and notice how many are about exactly the opt-out and consent issues a cookie-compliance setup is designed to handle:
| Company | When | Amount | What went wrong (in plain terms) |
|---|---|---|---|
| General Motors | May 2026 | $12.75M | Sold drivers’ location and behavior data without proper notice or consent. Largest CCPA fine to date |
| Disney/ABC | February 2026 | $2.75M | Its opt-out and browser do-not-sell signals didn’t actually stop data-sharing across devices and services |
| PlayOn Sports | March 2026 | $1.1M | Privacy regulator action over opt-out and consent failures |
| Ford | March 2026 | ~$376K | Forced people to verify their identity before opting out — which the law does not allow |
| Sephora | 2022 | $1.2M | Ignored the browser do-not-sell (GPC) signal. This was the original wake-up call. |
Sources: California attorney general and California Privacy Protection Agency announcements, reported via IAPP and legal industry analyses.4, 5, 6, 8
Why this should get your attention: California’s regulators now coordinate with other states, running a joint sweep to specifically check whether sites honor the browser do-not-sell signal. Regulators have signaled that fines may keep climbing so they won’t be treated as a routine cost of doing business.5 A new California delete request and opt-out platform for data brokers begins on August 1, 2026.11 The direction of travel is clearly toward more enforcement, not less.
5. Google changed the rules too
Privacy law isn’t the only thing pushing this forward: Google has tied its own advertising and analytics products to consent. If you run Google Ads or Google Analytics, two recent changes matter:
Google Consent Mode v2
This is Google’s system for letting your website tell Google whether a visitor has agreed to tracking. It’s required for European traffic, and it’s needed for popular features like Enhanced Conversions and remarketing regardless of where your visitors are.9 Without it set up correctly, Google quietly drops data — so your reporting and ad targeting get worse.
The June 15, 2026 change
As of June 15, 2026, Google made your website’s consent setup the main control over what data Google Ads is allowed to collect. A setting inside Google Analytics that some teams relied on as a backstop no longer plays that role.10 In plain terms: Your cookie-consent configuration is now central to both your compliance and your advertising performance. Getting it wrong is no longer just a legal risk — it directly affects how well your campaigns work.
The upside: A properly configured consent setup does double duty: It keeps you compliant, and by sending Google clean consent signals, it preserves the conversion data and audiences your ad campaigns depend on. Done right, compliance and performance pull in the same direction.
6. “Does this actually apply to us?”
Many of these laws formally kick in at thresholds such as handling the personal data of 100,000-plus residents of a state or earning a large share of revenue from selling data — and some laws carve out rules for business-to-business or employee data. So not every business is strictly covered by every law.1, 2
But here’s the practical reality: Website visitor counts add up faster than people expect; the rules differ state by state and are expanding every year; Google’s requirements and the browser do-not-sell signal apply regardless of your size; and a broken or missing consent setup is now one of the most visible, easily checked things a regulator (or a competitor or customer) can spot. For most businesses that run analytics or advertising, setting this up is low-cost insurance and simply good practice — not something to wait on.
7. What “good” looks like
A compliant, modern setup generally includes:
- A clear privacy notice and cookie policy saying what you collect and why
- A “Do not sell or share my personal information” option that actually works across your site
- Automatic detection of the browser do-not-sell (GPC) signal
- A consent tool wired to your tracking tags, so that analytics and ad tags respect each visitor’s choice
- Google Consent Mode v2 configured correctly, so compliance and ad performance work together
- A record of consent choices in case you ever need to show it
8. The bottom line
The patchwork of U.S. privacy laws is now broad enough, and enforcement is active enough, that “We’ll deal with it later” is the risky choice. The encouraging news is that for a typical U.S.-focused business, getting compliant is straightforward and affordable. A modern consent tool, configured once for the U.S. opt-out approach, handles the law and protects your advertising data at the same time.
If you’d like, we can review your site(s), recommend the simplest setup for your situation, and handle the implementation end to end. If we already manage advertising or websites for you, this fits naturally into that work.
Sources and further reading
These are independent legal, regulatory, and industry sources. They are provided so you can read the details yourself; they are not a substitute for advice from your own attorney.
- IAPP — U.S. state privacy requirements coming online as 2026 begins. https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins
- MultiState — State privacy laws in effect in 2026. https://www.multistate.us/insider/2026/2/4/all-of-the-comprehensive-privacy-laws-that-take-effect-in-2026
- Gunster — 2026 U.S. data privacy developments and universal opt-out requirements. https://www.gunster.com/newsroom/publications/2026-data-privacy-laws-state-changes-universal-opt-out-compliance
- IAPP — California authorities announce largest CCPA fine to date (General Motors, $12.75M). https://iapp.org/news/a/california-authorities-announce-largest-ccpa-fine-to-date
- IAPP — California’s attorney general issues largest CCPA fine to date (Disney, $2.75M). https://iapp.org/news/a/california-s-attorney-general-issues-largest-ccpa-fine-to-date
- PrivacyLawMap — 2026 CCPA enforcement wave (Disney, PlayOn Sports, Ford). https://privacylawmap.com/blog/ccpa-enforcement-wave-2026
- Clym — CCPA penalties and fines in 2026. https://www.clym.io/blog/ccpa-penalties-and-fines-what-businesses-need-to-know
- California Attorney General — Privacy enforcement actions (official list). https://oag.ca.gov/privacy/privacy-enforcement-actions
- Google Analytics Help — Verify and update consent settings (Consent Mode v2). https://support.google.com/analytics/answer/14275483
- Industry analysis — GA4 and Google Ads consent control changes effective June 15, 2026. https://almcorp.com/blog/ga4-google-ads-consent-controls-split-june-2026/
- Hunton — Record $12.75M GM settlement and California’s August 1, 2026 data broker platform. https://www.hunton.com/privacy-and-cybersecurity-law-blog/california-ag-announces-record-12-75m-settlement-with-gm-over-ccpa-data-minimization-and-purpose-limitation-violations
Please note: TECH B2B Marketing is a marketing agency, not a law firm. This briefing is general information to help you understand the current landscape — it is not legal advice. For questions about how these laws apply to your specific business, please consult a qualified attorney.
Contact Us Today
Need help with website privacy compliance and cookie consent? Contact us today.
“Privacy compliance isn't just about avoiding fines. Done right, it protects both your business and your marketing performance.”

























